awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
Back to zeek/zeek-agent

Projects sharing features with Zeek Agent

12 open-source projects similar to zeek/zeek-agent, ranked by shared indexed features. Tags may describe platforms or build tools rather than the same primary purpose. Check each project’s use case, license, and deployment requirements before treating it as a replacement.

  • draios/sysdigdraios avatar

    draios/sysdig

    8,261View on GitHub↗

    Sysdig is a Linux system observability tool and kernel event analyzer designed for capturing and analyzing kernel-level system calls and operating system events. It functions as a system call tracer and container security monitor, providing deep visibility into the activity of machines, virtual machines, and containers. The project specializes in non-invasive container inspection, allowing for the monitoring of container activity and resource usage without modifying the container environment or adding instrumentation. It enables the recording of detailed system traces into binary files for re

    C++
    View on GitHub↗8,261
  • kolide/fleetkolide avatar

    kolide/fleet

    1,098View on GitHub↗

    A flexible control server for osquery fleets

    hacktoberfesthost-instrumentationinfosec
    View on GitHub↗1,098
  • mhaggis/sysmon-dfirM

    mhaggis/sysmon-dfir

    0View on GitHub↗
    View on GitHub↗0
  • neo23x0/auditdNeo23x0 avatar

    Neo23x0/auditd

    1,854View on GitHub↗

    Best Practice Auditd Configuration

    Shell
    View on GitHub↗1,854
  • olafhartong/sysmon-modularolafhartong avatar

    olafhartong/sysmon-modular

    3,057View on GitHub↗

    A repository of sysmon configuration modules

    PowerShell
    View on GitHub↗3,057

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Find more with AI search
osquery/osqueryosquery avatar

osquery/osquery

23,113View on GitHub↗

Osquery is a unified endpoint monitoring framework that exposes operating system internals as relational tables. By representing hardware, network, and process activity as structured data, it allows users to retrieve system state and configuration information using standard SQL syntax. The system distinguishes itself through a cross-platform abstraction layer that normalizes disparate operating system interfaces into a consistent schema across Windows, macOS, and Linux. It supports both interactive local analysis via a command-line shell and distributed fleet orchestration, where recurring qu

C++hacktoberfestintrusion-detectionmonitoring
View on GitHub↗23,113
  • ossec/ossec-hidsO

    ossec/ossec-hids

    0View on GitHub↗

    OSSEC v4.1.0

    View on GitHub↗0
  • palantir/osquery-configurationP

    palantir/osquery-configuration

    0View on GitHub↗
    View on GitHub↗0
  • slackhq/go-auditslackhq avatar

    slackhq/go-audit

    1,660View on GitHub↗

    go-audit is an alternative to the auditd daemon that ships with many distros

    Go
    View on GitHub↗1,660
  • swiftonsecurity/sysmon-configSwiftOnSecurity avatar

    SwiftOnSecurity/sysmon-config

    5,398View on GitHub↗

    sysmon-config provides configuration templates and exclusion rule sets designed to standardize system event tracing and reduce log noise on Windows hosts. It functions as a security configuration baseline that establishes a standard for tracing system events and process behaviors. The project focuses on providing pre-defined XML filters to highlight anomalous system changes while minimizing performance impact. It utilizes a collection of exclusion rules to remove trusted processes from event logs, which improves signal quality and reduces the volume of generated security data. These configur

    loggingmonitoringnetsec
    View on GitHub↗5,398
  • velocidex/velociraptorVelocidex avatar

    Velocidex/velociraptor

    3,769View on GitHub↗

    Velociraptor is a digital forensics and incident response platform, endpoint detection and response system, and visibility tool. It provides a query engine and remote forensic collector used to hunt for indicators of compromise and perform triage across a fleet of hosts. The system is distinguished by its specialized query language for interrogating host state and parsing binary files. It features a notebook environment that combines markdown documentation with executable query cells to standardize investigative workflows and enable collaborative reporting. The platform covers a wide range o

    Godigital-forensicsendpoint-discoveryendpoint-protection
    View on GitHub↗3,769
  • wazuh/wazuhwazuh avatar

    wazuh/wazuh

    14,779View on GitHub↗

    Wazuh is an integrated security platform that combines endpoint detection and response, security information and event management, and cloud workload protection. It functions as a centralized system for collecting telemetry, aggregating logs, and correlating events across distributed infrastructure to maintain security and integrity. The platform distinguishes itself through its active response orchestration, which allows for the automated execution of scripts on remote endpoints to neutralize threats in real time. It provides deep visibility into system activity through file integrity monito

    Ccloud-securitycomplianceconfiguration-assessement
    View on GitHub↗14,779